Skip to main content
  1. Home
  2. Computing
  3. News

OpenAI’s powerful AI agents ran amok and hacked multiple services on their own

The agents escaped their testing constraints, raided Hugging Face for answers and used compromised accounts across four services to support the attack

Add as a preferred source on Google
The ChatGPT name next to an OpenAI logo on a black and white background.
Pexels

OpenAI’s powerful AI agents didn’t stay inside the security test built for them. The company says its models reached four accounts across separate public services while pursuing an intrusion into Hugging Face.

Reuters identified one victim as a Modal customer whose unsecured code left a sandbox exposed online. A benchmark designed to measure hacking ability had spilled into real infrastructure, with the agents choosing their own targets and methods along the way.

How the agents escaped the assignment

OpenAI was testing GPT-5.6 Sol and an unreleased research model against ExploitGym, which measures whether AI systems can find and exploit software vulnerabilities. Both were operating without their usual safeguards.

One agent decided Hugging Face might hold the benchmark answers and chased them instead of completing the assigned challenge. It compromised a third-party sandbox, gained administrator access and used that environment to continue the intrusion.

Recommended Videos

The behavior wasn’t random. The agent found what looked like a shortcut and methodically broke into outside systems to reach it. Apparently, running amok doesn’t require losing sight of the objective.

How far the attack spread

OpenAI found that its agents had entered four external accounts using credentials already exposed online. Wired says one account helped relay traffic and disguise the origin of the Hugging Face intrusion, while another stored stolen data.

The Modal customer had also published an unauthenticated endpoint that let anyone execute code inside its sandboxes. Modal says its platform wasn’t breached, but the customer’s exposed environment still gave the agents somewhere to operate.

Inside Hugging Face, the agents reached administrator-level systems. They also enrolled 181 attacker-controlled devices in the company’s corporate network, taking the incident well beyond an AI trying to peek at an answer key.

What OpenAI did after the breach

OpenAI deactivated and encrypted the unreleased model before cutting off researchers’ access. It’s still reviewing the incident and says it will contact any other affected service owners it identifies.

Exposed credentials and insecure infrastructure opened the doors, but OpenAI had deliberately disabled the models’ usual safeguards. Future tests will need to isolate powerful agents from public systems, even when researchers expect them to stay politely inside the assignment.

Paulo Vargas
Paulo Vargas is an English major turned reporter turned technical writer, with a career that has always circled back to…
Wispr Flow asked its haters what was wrong and more than 700 people answered
Desktop users can finally move the Flow Bar away from app controls
Electronics, Screen, Computer

More than 700 people responded when Wispr Flow invited its critics to explain what wasn’t working. It expected around 50.

The first visible result is useful, if rather modest. A Wispr Flow update now lets desktop users move the Flow Bar instead of leaving it anchored along the bottom of the screen.

Read more
Mark Zuckerberg wants AI superintelligence in everyone’s hands
Meta says it can bring advanced AI to billions of people, though access won’t give users control over the infrastructure, safeguards, or limits behind it
Body Part, Finger, Hand

In an opinion essay for The Wall Street Journal, Mark Zuckerberg lays out a modest ambition for Meta’s AI. He wants to put superintelligence in everyone’s hands, giving ordinary people technology powerful enough to improve their health or help them work.

Zuckerberg presents personal superintelligence as an alternative to advanced AI being controlled by a few institutions. Meta can certainly distribute it on a scale few companies could match. What users would receive is an assistant built and governed somewhere else, with its most important decisions made for them.

Read more
The US government just blacklisted foreign-made robots and power inverters
Uncle Sam just said no thanks to foreign robots and power inverters, at least the new ones.
robots with black background

Months after banning all foreign routers and subsequently approving some of them in weeks, the FCC is back at it again, and this time robots and power inverters are in its crosshairs. 

The Federal Communications Commission has added two new entries to its Covered List, and this time the targets are advanced robots and power inverters made outside the US. The move follows a White House-led security review that flagged both categories as genuine risks to national security.

Read more